Wordpress

Wordpress

360 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 6.69%
  • Veröffentlicht 09.01.2007 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

WordPress before 2.0.6, when mbstring is enabled for PHP, decodes alternate character sets after escaping the SQL query, which allows remote attackers to bypass SQL injection protection schemes and execute arbitrary SQL commands via multibyte charset...

  • EPSS 1.34%
  • Veröffentlicht 09.01.2007 00:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.

Exploit
  • EPSS 3.48%
  • Veröffentlicht 28.12.2006 21:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in wp-admin/templates.php in WordPress 2.0.5 allows remote attackers to inject arbitrary web script or HTML via the file parameter. NOTE: some sources have reported this as a vulnerability in the get_file_des...

  • EPSS 0.75%
  • Veröffentlicht 21.11.2006 23:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

wp-admin/user-edit.php in WordPress before 2.0.5 allows remote authenticated users to read the metadata of an arbitrary user via a modified user_id parameter.

  • EPSS 2.82%
  • Veröffentlicht 21.11.2006 23:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

WordPress before 2.0.5 does not properly store a profile containing a string representation of a serialized object, which allows remote authenticated users to cause a denial of service (application crash) via a string that represents a (1) malformed ...

  • EPSS 4.7%
  • Veröffentlicht 04.11.2006 01:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple directory traversal vulnerabilities in plugins/wp-db-backup.php in WordPress before 2.0.5 allow remote authenticated users to read or overwrite arbitrary files via directory traversal sequences in the (1) backup and (2) fragment parameters i...

  • EPSS 0.86%
  • Veröffentlicht 13.09.2006 22:07:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.php, (2) akismet.php, (3) archive.php, (4) archives.php, (5) attachment.php, (6) blogger.php, (7) comments.php, (8) comments-popup....

  • EPSS 5.59%
  • Veröffentlicht 09.08.2006 20:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Multiple unspecified vulnerabilities in WordPress before 2.0.4 have unknown impact and remote attack vectors. NOTE: due to lack of details, it is not clear how these issues are different from CVE-2006-3389 and CVE-2006-3390, although it is likely th...

  • EPSS 1.2%
  • Veröffentlicht 06.07.2006 20:05:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an invalid paged parameter, which displays the information in an SQL error message. NOTE: this issue has been disputed by a third p...

  • EPSS 1.36%
  • Veröffentlicht 06.07.2006 20:05:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as those in the (1) wp-admin, (2) wp-content, and (3) wp-includes directories, possibly due to uninitialized variables.